plugin

Acf To Rest Api Vulnerabilities

3 known security issues reported for the Acf To Rest Api WordPress plugin. Most recent disclosed Jan 6, 2026.

1 high 2 medium

Running Acf To Rest Api on your site? Check whether your installed version is affected.

Scan your site free

ACF to REST API <= 3.3.4 - Insecure Direct Object Reference to Authenticated (Contributor+) ACF Field/Option Modification

medium

The ACF to REST API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.4. This is due to insufficient capability checks in the update_item_permissions_check() method, which only verifies that the current user has the edit_posts capability without checking ob...

CVSS:
4.3
Affected:
up to 3.3.4
Fix:
No patched version reported
Disclosed:
Jan 6, 2026

CVE-2025-12030 on NVD →

ACF to REST API <= 3.3.4 - Unauthenticated Information Exposure

medium

The ACF to REST API plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.4. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 3.3.4
Fix:
No patched version reported
Disclosed:
Oct 20, 2025

CVE-2025-62979 on NVD →

ACF to REST API <= 3.2.0 - Insecure direct object reference via permalinks manipulation

high

An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that reads sensitive information in the wp_options table, such as the login and pass values. Issue was finall...

CVSS:
7.5
Affected:
up to 3.2.0
Fixed in:
3.3.0
Disclosed:
May 29, 2020

CVE-2020-13700 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database